CVE-2018-20796: High severity gnu c library (glibc) vulnerability
In the GNU C Library (aka glibc or libc6) through 2.29, checkdstlimitscalcpos1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-20796?
CVE-2018-20796 is a vulnerability in the GNU C Library (glibc) through version 2.29 that allows for uncontrolled recursion, leading to potential denial of service or arbitrary code execution.
How does CVE-2018-20796 impact affected systems?
CVE-2018-20796 can affect systems that rely on the affected versions of the GNU C Library (glibc), potentially leading to denial of service or arbitrary code execution.
What is the severity of CVE-2018-20796?
CVE-2018-20796 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2018-20796?
Versions of GNU glibc up to and including 2.29, NetApp Cloud Backup, NetApp ONTAP Select Deploy administration utility, and NetApp Steelstore Cloud Integrated Storage are affected by CVE-2018-20796.
How can I mitigate or fix CVE-2018-20796?
To mitigate CVE-2018-20796, it is recommended to upgrade to a patched version of the GNU C Library (glibc), if available, or follow the guidance provided by the software vendor for the affected software.